Purpose-built model for leaked secret detection
By Steven Van ·
Existing AI-detected alerts stay included in GHSP and GHAS, while new opt-in checks will consume GitHub AI Credits.
Customers using AI-detected Password alerts in GitHub have automatically moved to a new model that reads surrounding code to identify likely credentials, including passwords without a recognizable token format. The model detects secrets without generating code or prose.
Alerts and push protection
AI-detected secret alerts remain included in GitHub Secret Protection (GHSP) and GitHub Advanced Security (GHAS) at no additional charge. The model will also bring AI-detected alerts to GitHub Enterprise Server 3.23 in public preview, included with an enterprise’s existing GHSP and GHAS purchase.
AI-detected secrets in push protection are available in private preview. These checks look for unstructured credentials at push time, giving developers a chance to remove a secret before it enters repository history.
Secret scanning in security reviews
AI-based secret scanning through the Copilot CLI and Copilot app’s /security-review command is coming soon in private preview. The command itself is already in public preview. The app documentation describes running it in an active session with in-progress code changes to receive prioritized vulnerability findings, severity and confidence scores, and suggested fixes that can be applied and verified in the same session.
Credits for opt-in checks
The new opt-in push protection and security review checks will consume GitHub AI Credits, with credit usage introduced in the coming weeks. Existing AI-detected secret alert scans remain included in GHSP and GHAS without an additional charge.
